A service connection is a stored credential that any authorized pipeline can exercise. In practice, 'authorized' often means 'every pipeline in the project' — one checkbox at creation time made sure of that. Attackers who compromise a build do not need to steal secrets when the build is already allowed to act as one.
Where governance breaks down
- 'Grant access permission to all pipelines' — convenient at creation, invisible afterwards.
- Connections created per team with nobody tracking scope or ownership.
- Stored secrets that outlive rotation policies because nothing inventories them.
- Security integrations whose own connections are configured once and never reviewed.
A workable governance loop
Inventory every connection and its pipeline grants. Prefer workload identity federation over stored secrets where the target supports it. Alert on new broad grants. And synchronize the connections your security tooling depends on, so a renamed or re-scoped connection does not silently sever scanning.
The Kangl angle
Kangl inventories service connections as part of the Azure DevOps estate, keeps the connections used by managed security integrations synchronized, and records connection-related operations in the audit history. The credential your scanning depends on stops being a single point of silent failure.

